<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:27:42 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12864</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12864</link>
      <description>bdu:2026-12864</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12864</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-47770</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-47770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: jq, Alpaquita:25: jq, Alpaquita:stream: jq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: jq, Alpaquita:25: jq, Alpaquita:stream: jq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-47770</guid>
    </item>
    <item>
      <title>EUVD-2026-330748</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330748</link>
      <description>EUVD-2026-330748</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330748</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47770</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47770</link>
      <description>&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;#39;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;#39;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;#39;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;#39;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47770</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-47770 — jq: stack overflow in deep structural equality</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-47770</link>
      <description>msrc_CVE-2026-47770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-47770</guid>
    </item>
    <item>
      <title>OESA-2026-2803 — jq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2803</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: jq&lt;/p&gt;
&lt;p&gt;jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;amp;apos;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;amp;apos;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.(CVE-2026-47770)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: jq&lt;/p&gt;
&lt;p&gt;jq is a lightweight and flexible command-line JSON processor. you can use it to slice and filter and map and transform structured data. It is written in portable C, and it has zero runtime dependencies. it can mangle the data format that you have into the one that you want.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;amp;apos;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;amp;apos;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.(CVE-2026-47770)&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2803</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11133-1 — jq-1.8.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11133-1</link>
      <description>&lt;p&gt;jq-1.8.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq-1.8.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11133-1</guid>
    </item>
    <item>
      <title>RHSA-2026:29986 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:29986</link>
      <description>&lt;p&gt;jq: stack overflow via unbounded recursion in jv_contains jq: embedded NUL truncates top-level jq programs loaded with -f jq: signed-int overflow in stack_reallocate jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts jq: stack overflow in recursive object merge jq: stack overflow in module loading on mutual include jq: jq: Denial of Service via deeply nested array comparison jq: jq: Heap out-of-bounds write via oversized raw file processing jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jq: stack overflow via unbounded recursion in jv_contains jq: embedded NUL truncates top-level jq programs loaded with -f jq: signed-int overflow in stack_reallocate jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts jq: stack overflow in recursive object merge jq: stack overflow in module loading on mutual include jq: jq: Denial of Service via deeply nested array comparison jq: jq: Heap out-of-bounds write via oversized raw file processing jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:29986</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23671-1 — Security update for jq</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23671-1</link>
      <description>&lt;p&gt;Security update for jq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for jq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23671-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-47770</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jq, Ubuntu:Pro:16.04:LTS: jq, Ubuntu:Pro:18.04:LTS: jq, Ubuntu:Pro:20.04:LTS: jq, Ubuntu:22.04:LTS: jq, Ubuntu:24.04:LTS: jq, Ubuntu:25.10: jq, Ubuntu:26.04:LTS: jq&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;#39;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;#39;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jq, Ubuntu:Pro:16.04:LTS: jq, Ubuntu:Pro:18.04:LTS: jq, Ubuntu:Pro:20.04:LTS: jq, Ubuntu:22.04:LTS: jq, Ubuntu:24.04:LTS: jq, Ubuntu:25.10: jq, Ubuntu:26.04:LTS: jq&lt;/p&gt;
&lt;p&gt;jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq&amp;#39;s ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq&amp;#39;s recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-47770</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1664 — jq: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1664</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jq ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in jq ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1664</guid>
    </item>
  </channel>
</rss>
